Skip to content

chore: release main - #1713

Merged
mldangelo merged 3 commits into
mainfrom
release-please--branches--main
Jun 24, 2026
Merged

mldangelo merged 3 commits into
mainfrom
release-please--branches--main

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

🤖 I have created a release beep boop

0.2.48

0.2.48 (2026-06-24)

Bug Fixes

  • accept gzip-framed NeMo archives (#1634) (7be6b46)
  • audit dependencies for source changes (#1535) (bf1e109)
  • avoid exact-budget cloud pickle false positives (#1595) (350baa0)
  • bind direct shard cache to siblings (#1543) (45bf167)
  • bound executorch zip scanning (#1546) (ff9e1ae)
  • bound jinja scalar range render probes (#1553) (c00542e)
  • bound joblib decompression output (#1522) (98f41b1)
  • bound keras zip config traversal (#1555) (6e6ba57)
  • bound manifest jinja collection traversal (#1561) (23b6ca2)
  • bound OCI layer extraction budgets (#1566) (5f96b42)
  • bound picklescan pytorch zip members (#1569) (322c01b)
  • bound protocol0 line operands (#1534) (95e27df)
  • bound sevenzip member name collection (#1574) (fb36ad8)
  • bound stream analysis reads (#1525) (d44deb8)
  • bound weight distribution tensor extraction (#1581) (dc0051c)
  • calibrate legacy PyTorch storage persistent IDs (#1652) (4a28b7f)
  • calibrate onnx custom domain findings (149cde4)
  • calibrate validated ONNX alternate framing (59ec990)
  • ci: raise test job timeout for instrumented main lane (#1625) (94e98ca)
  • clarify and enforce telemetry privacy (#1592) (33186db)
  • classify pytorch zip symlink targets (#1573) (c7e1699)
  • classify tar link escapes as symlinks (#1578) (edb65b2)
  • classify text sidecar security findings (#1465) (a3a561c)
  • cli: make streaming dry runs non-executing (c0059d8)
  • close authorization evidence redaction gaps (#1596) (4606b59)
  • close JIT replay review gaps (#1519) (69928bc)
  • close network redaction follow-up gaps (#1518) (c6fa017)
  • cloud: bound directory analysis before download (#1621) (7bf4531)
  • constrain direct sharded symlink expansion (#1463) (9a9f1df)
  • contain cloud object download paths (#1541) (17efed9)
  • contain mlflow download return paths (#1563) (4239134)
  • contextualize SafeTensors license metadata (#1661) (0904a91)
  • deduplicate onnx custom domain findings (#1656) (2bca0c0)
  • deps: require msgpack 1.2.1 (#1705) (d028a15)
  • deps: update rust crate pyo3 to 0.29.0 [security] (#1677) (a2fe49c)
  • detect explicit keras get_file tar extraction (#1556) (e15963f)
  • detect flax msgpack byte keys (#1548) (e640403)
  • detect operator archive Python execution paths (#1538) (ae81048)
  • detect pickle binunicode8 setitem abuse (#1524) (43d2fb8)
  • disable unsafe metadata deserialization (#1523) (5cf4945)
  • discover hidden executorch pickle members (#1547) (1f2059f)
  • dispatch logical model directory scanners (45532e3)
  • distrust Keras artifact runtime versions (#1559) (fd38c3b)
  • docker: preserve native architecture fallback (#1690) (8a466f4)
  • docker: update Python digest and honor target architecture (#1687) (303f7c1)
  • enforce MLflow acquisition budgets (#1442) (0d38924)
  • enforce MLflow artifact backend allowlist (#1564) (74ebeae)
  • escape text output controls (#1580) (164bbb9)
  • exclude Hugging Face cache sidecars (00dcc11)
  • fail closed on capped DVC outputs (#1472) (f854808)
  • fail closed on invalid joblib trusted tails (#1554) (4e957b0)
  • fail closed on nested protocol0 operand limits (#1536) (c018c26)
  • fail closed on raw detector errors (#1457) (85e7c8c)
  • fail closed on unresolved DVC outputs (#1488) (d3dd63f)
  • fail closed when keras h5 lacks h5py (#1432) (0e81de7)
  • fail gated Hugging Face acquisitions honestly (#1646) (8192304)
  • gguf: calibrate metadata string findings (f3e77e4)
  • harden cloud acquisition routing budgets (#1540) (d958807)
  • harden Flax regex streaming (#1600) (0c69e69)
  • harden JFrog redirect targets (#1520) (ea54e39)
  • harden Keras H5 CVE coverage (#1558) (54fd488)
  • harden large tokenizer JSON EOF ownership proof (#1695) (9edbaba)
  • harden NeMo Hydra helper arguments (#1565) (787a1ab)
  • harden NeMo Hydra I/O analysis (#1426) (6670ad3)
  • harden pickle CVE stream probing (#1603) (76352d7)
  • harden picklescan spec resolution (#1568) (b5b1355)
  • harden R named argument detection (#1510) (5c4c4ae)
  • harden streamed TAR and NeMo inspection (#1665) (c52b914)
  • harden telemetry privacy redaction (#1579) (532ae59)
  • huggingface: avoid probes for selection-skipped shards (#1633) (94a89df)
  • inspect large ONNX models without full reads (#1664) (5befbef)
  • invalidate pickle cache on source changes (#1447) (beac45c)
  • isolate legacy pytorch storage controls (#1699) (1a9b556)
  • jinja: require executable SSTI context (#1647) (4cd9a18)
  • jit: bound alias replay before safe runpy calls (#1685) (7bd62ec)
  • jit: bound passive reference replay (#1681) (e542e54)
  • keep sentencepiece tokenizers out of xgboost routing (5ac9efc)
  • llamafile: stream executable runtime coverage (#1622) (8d6c486)
  • manifest: fail closed on scan timeout (#1615) (c769097)
  • onnx: classify custom operator domains (#1614) (d5a6ac2)
  • onnx: reduce weight anomaly noise (#1608) (d5ae100)
  • paginate large Hugging Face inventories (e393dc0)
  • pickle: bound legacy PyTorch control streams (#1619) (e407fb4)
  • pickle: require source proof for framework metadata (bb38b74)
  • picklescan: bound hidden ZIP probe bytes (#1624) (e8dc55e)
  • picklescan: close encoded protocol0 probe gaps (#1594) (dfaedd1)
  • picklescan: fail closed at nested depth limits (#1583) (5eb7390)
  • picklescan: fail closed on unverifiable stream boundaries (#1521) (9cd9e67)
  • picklescan: harden encoded byte probes (#1604) (f8192be)
  • picklescan: ignore short base64 collisions (#1617) (1d1a93d)
  • picklescan: mirror cached path importer semantics (#1683) (b948f8c)
  • picklescan: preserve nested INST limit findings (#1585) (68d1d19)
  • picklescan: reject padded short payload bypasses (#1626) (4edcac0)
  • picklescan: resolve loaded extension exports directly (#1620) (ab6e58e)
  • picklescan: safely filter inert URL metadata (#1658) (8a55653)
  • picklescan: scan encoded byte literals (#1602) (21956ab)
  • picklescan: validate canonical PyTorch ZIP tensor rebuilds (#1680) (2f188ad)
  • preflight generic zip entry limits (#1549) (9da67c9)
  • preserve active HF correlation findings (#1551) (603c782)
  • preserve active HF findings (#1601) (29af2de)
  • preserve default scanner read caps (#1542) (c55de21)
  • preserve ONNX external data in HF streaming (#1635) (67fd0d4)
  • preserve OpenVINO companions in HF streaming (#1642) (2a2aebc)
  • preserve unusual docs filenames in formatter (#1533) (e1b066d)
  • prevent CatBoost credential-redaction ReDoS (#1584) (493436e)
  • preview Hugging Face dry-run scans (#1645) (fd40a81)
  • pytorch: aggregate exact pickle opcodes (#1611) (3728964)
  • pytorch: distinguish producer metadata from runtime CVEs (#1643) (beb34c6)
  • pytorch: stream bounded analysis of large legacy shards (93c0e5b)
  • pytorch: trust referenced storage members (#1654) (3a4f64b)
  • recognize GGUF BF16 tensor type (#1632) (05443d2)
  • reconcile cross-directory model shards (#1587) (b143688)
  • redact authorization evidence variants (#1544) (f3ad852)
  • redact CatBoost evidence secrets (#1428) (5e56d8a)
  • redact exported source identifiers (#1530) (6f4407d)
  • redact Keras and TensorFlow scanner evidence (#1560) (8e9d119)
  • redact keras h5 lambda previews (#1435) (9830ef6)
  • redact mlflow download errors (#1562) (5067f88)
  • redact network finding snippets (#1438) (36f26f0)
  • redact stream source urls (#1429) (77b2295)
  • reduce JIT script detector false positives and negatives (#1513) (0984542)
  • reject cleartext remote model sources (#1527) (6524032)
  • reject jfrog folder local path collisions (#1552) (e22f4e1)
  • reject symlinked CLI report outputs (#1485) (d4003a6)
  • reject undersized nested pickle budgets (#1532) (0ce9bf3)
  • report complete Hugging Face inventory capabilities (#1648) (d8888d1)
  • require defusedxml for pmml parsing (#1570) (b8053d6)
  • require explicit opt-in for PyTorch weight loading (#1582) (067dcba)
  • restore cross-platform scanner baselines (#1597) (2484ac7)
  • restore main CI coverage (#1606) (c81db69)
  • restrict auth bearer token hosts (#1539) (838f250)
  • restrict manual docker publish tags (#1526) (1abc856)
  • restrict progress hook egress (#1571) (bc9419e)
  • results: isolate nested member integrity hashes (#1666) (50e2df3)
  • results: propagate inconclusive file coverage (#1672) (4ab592f)
  • route protocol-less binary pickles (#1577) (ff68cb0)
  • routing: bound tokenizer json scanner selection (#1638) (e47be19)
  • routing: classify tokenizer text before binary formats (#1629) (067717d)
  • routing: keep media out of serialized scanners (0a65650)
  • routing: keep text assets out of Flax MessagePack (34cad20)
  • routing: prefer validated safetensors framing (#1612) (2f782ba)
  • rules: attribute format mismatches to s901 (#1613) (22bc654)
  • safetensors: accept current tensor dtypes (#1610) (fd6f0ea)
  • safetensors: accept empty tensor offsets (#1607) (9d547bb)
  • safetensors: prefer bounded framing over zlib magic (#1623) (54b01e1)
  • scan ExecuTorch raw payload indicators (#1545) (c37246d)
  • scan model links in oci layers (#1567) (f85e0ef)
  • scripts: contain corpus QA output paths (#1618) (a33b710)
  • scripts: quote whitelist model ids safely (#1616) (8f57897)
  • sniff Hugging Face selective downloads (#1412) (9576eb7)
  • stream Flax msgpack analysis (#1589) (0c13d9e)
  • stream Hugging Face SafeTensors shard headers (#1667) (e6186dc)
  • stream large Flax MessagePack tensors (16e1bec)
  • stream large Keras HDF5 inspection (0ff7b62)
  • strictly pin picklescan maturin backend (#1531) (ac07522)
  • text: contextualize tokenizer vocabulary indicators (#1653) (13431e4)
  • text: deduplicate model-card indicators (#1631) (5ff4247)
  • text: ignore pip version pins in documentation (#1630) (45e6d62)
  • text: validate basic auth credential context (#1669) (a675581)
  • tolerate picklescan reports without private metadata (cdc8b8b)
  • validate hf direct url paths (#1550) (def9169)
  • validate OCI layer member metadata (#1444) (a7235e1)
  • validate pickle getattr reconstruction (c6c4713)
  • verify rustup installer in docker builds (#1529) (51f2336)

Performance Improvements

  • hashing: read in 8 MB chunks instead of 8 KB (#1709) (6caa259)

Documentation

modelaudit-picklescan: 0.1.7

0.1.7 (2026-06-24)

Bug Fixes

  • bound picklescan pytorch zip members (#1569) (322c01b)
  • bound protocol0 line operands (#1534) (95e27df)
  • contextualize SafeTensors license metadata (#1661) (0904a91)
  • deps: update rust crate pyo3 to 0.29.0 [security] (#1677) (a2fe49c)
  • fail closed on nested protocol0 operand limits (#1536) (c018c26)
  • harden picklescan spec resolution (#1568) (b5b1355)
  • invalidate pickle cache on source changes (#1447) (beac45c)
  • isolate legacy pytorch storage controls (#1699) (1a9b556)
  • pickle: require source proof for framework metadata (bb38b74)
  • picklescan: bound hidden ZIP probe bytes (#1624) (e8dc55e)
  • picklescan: close encoded protocol0 probe gaps (#1594) (dfaedd1)
  • picklescan: fail closed at nested depth limits (#1583) (5eb7390)
  • picklescan: fail closed on unverifiable stream boundaries (#1521) (9cd9e67)
  • picklescan: harden encoded byte probes (#1604) (f8192be)
  • picklescan: ignore short base64 collisions (#1617) (1d1a93d)
  • picklescan: mirror cached path importer semantics (#1683) (b948f8c)
  • picklescan: preserve nested INST limit findings (#1585) (68d1d19)
  • picklescan: reject padded short payload bypasses (#1626) (4edcac0)
  • picklescan: resolve loaded extension exports directly (#1620) (ab6e58e)
  • picklescan: safely filter inert URL metadata (#1658) (8a55653)
  • picklescan: scan encoded byte literals (#1602) (21956ab)
  • picklescan: validate canonical PyTorch ZIP tensor rebuilds (#1680) (2f188ad)
  • pytorch: aggregate exact pickle opcodes (#1611) (3728964)
  • pytorch: trust referenced storage members (#1654) (3a4f64b)
  • reject undersized nested pickle budgets (#1532) (0ce9bf3)
  • restore main CI coverage (#1606) (c81db69)
  • routing: prefer validated safetensors framing (#1612) (2f782ba)
  • strictly pin picklescan maturin backend (#1531) (ac07522)
  • text: validate basic auth credential context (#1669) (a675581)
  • validate pickle getattr reconstruction (c6c4713)

Documentation


This PR was generated with Release Please. See documentation.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: ba3df4d773

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread pyproject.toml
[project]
name = "modelaudit"
version = "0.2.47"
version = "0.2.48"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Update uv.lock with the release version

This bumps the root package to 0.2.48, but the committed root lockfile still records name = "modelaudit" with version = "0.2.47" at uv.lock:2408-2409. The repo treats pyproject.toml and uv.lock as the root version sources, so release validation or any lane that checks/builds from the lock will see stale package metadata until uv.lock is refreshed and committed with this bump.

Useful? React with 👍 / 👎.

@mldangelo
mldangelo merged commit a5536a9 into main Jun 24, 2026
1 check passed
@mldangelo
mldangelo deleted the release-please--branches--main branch June 24, 2026 14:35
@github-actions

Copy link
Copy Markdown
Contributor Author

🤖 Created releases:

🌻

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant